PlumbTrackLive demoGRC Risk System

← control library

Developer Configuration Management SA-10

System and Services Acquisition · Moderate baseline ✗ Not implemented

Status — program-wide

What references this control

No risks name this control in their Framework field yet.

No policies reference it yet.


Link a risk or policy to this control

Attaching adds SA-10 to the item's Framework field; the ✨ AI button suggests the best match. You can also edit the Framework field on a risk / policy directly.

Source: NIST SP 800-53 Rev.5, System and Services Acquisition family NIST SP 800-53 Rev.5. The baseline shows the lowest SP 800-53B baseline (Low / Moderate / High) this control appears in NIST SP 800-53B.

Control guide — plain-English, per NIST SP 800-53

SA-10 (Developer Configuration Management) asks whoever builds a system — including you, when you write the scripts and configs that stand this server up — to manage changes on purpose. That means controlling the integrity of what changes, applying only approved changes, recording each change and its security impact, and tracking flaws through to a fix. Here, ‘configuration management’ is the discipline of versioning and controlling changes, not a single tool. It enters at the Moderate baseline.

What good looks like

Framework mapping

How to move it toward Implemented